Notice of Pre-AIA or AIA Status
The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA .
Detailed action
Claims 1-18 are pending and being considered.
Claims 1, 4, 10, 11, 14-17 have been amended.
Claim 18 have been newly added.
The net title submitted on 06/22/2026 have been accepted.
112f interpretation is withdrawn based on applicants’ amendments to the claims.
Response to 103
Applicant’s arguments filled on 06/22/2026 have been fully considered and are persuasive but are moot in view of new grounds of rejections. The arguments do not apply to the current art being used.
Claim Objections
Claims 1, 16 and 17 objected to because of the following informalities:
Claim 1, 16 and 17 recites the limitation “in response to determining that a predetermined time has elapsed from time at which the integrity check has been performed, subtract a preset value from the first reliability to change the current level among the at least two levels to diminish the degree of the security protection state indicated by the first reliability” the examiner suggest to clarify whether the preset value is subtracted when the integrity check has been successfully completed OR when the integrity check has not been successfully completed. Appropriate correction is required.
Claim Rejections - 35 USC § 103
The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action:
A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made.
Claims 1-8 and 13-18 are rejected under 35 U.S.C. 103 as being unpatentable over HAREL et al (hereinafter HAREL) (US 20230275877) in view of HAYTON et al (hereinafter HAYTON) (US 20180198604) and further in view of Minezaki (US 20160004554).
Regarding claim 1 HAREL teaches a monitoring system for monitoring a vehicle or an integrated electronic control unit (ECU) in which functions of a plurality of ECUs are integrated and that operates inside the vehicle (HAREL on [0011 and 0087] teaches system and method for monitoring ECUs in vehicle to protect against cyber security attack. See also on [0123] teaches system that monitors all traffic to and from the ECUs);
the integrated ECU being capable of operating a plurality of virtual machines, each of the plurality of virtual machines including a function of at least one ECU among functions of the plurality of ECUs (HAREL on [0023, 0115, 0119, 0123] teaches ECU operating plurality of virtual machine. See on [0104-0107] teaches the virtual machine 306, being a honeypot, may be configured with security and monitoring features so that, when a malicious attack is performed on the virtual machine 306, that attack is trapped or “sandboxed” within the virtual machine 306. Operations of the attack such as system calls, network communication, and the like can be recorded by the virtual machine 306. i.e., virtual machine with function of ECUs);
wherein the monitoring system comprises one or more processors and one or more memories (HAREL on [0003-0004 and 0142-0148] teaches electronic controller having processor and memory);
wherein the monitoring system comprises a reliability manager that handles one of the plurality of virtual machines as a first monitoring target for monitoring the functions of the plurality of ECUs (HAREL on [0088-0090] teaches an attack analyzer 106 can be configured to monitor the malicious attacks 102 on the trap-images 104 and record information about the attacks. The trap images 104 are images of software of ECUs that are to be hardened. See on [0104-0107] the virtual machine 306, being a honeypot, may be configured with security and monitoring features so that, when a malicious attack is performed on the virtual machine 306, that attack is trapped or “sandboxed” within the virtual machine 306. Operations of the attack such as system calls, network communication, and the like can be recorded by the virtual machine 306. i.e., virtual machine with function of ECUs. Further teaches an attack on the library 308 may attempt to use a buffer-overrun exploit to initiate execution of arbitrary code within the virtual machine 306. When this attack is attempted (whether successful or unsuccessful) the virtual machine 306 can record actions taken. In some cases, elements of the virtual machine are inaccessible to the environment in which the libraries 308 execute, and one or more supervisors in those elements monitor the actions in the environment. See on [0123] teaches the trap image server system 204 can monitor all network traffic to and from the ECUs. See on [0130 and 0135] teaches the hosting system can monitor network traffic and the state of the VM for events that match a rule-set of states indicative of a malicious attack);
and manages first reliability indicating a security protection state of the first monitoring target, the first reliability being a variable capable of taking at least two levels each of which indicates a degree of the security protection state of the first monitoring target (HAREL on [0174] teaches confidence value or metric that indicates a variable level of certainty that the information about a particular sign, road, restriction, limit, location, or other attribute or object is accurate. See on [0179 and 0192-0194] teaches , a newly added landmark may be given a low confidence level, such as 1%, 5%, or 10%, to prevent the information from being used to alter vehicular behavior until the landmark can be confirmed and high confidence level. i.e., at least two levels low and high indicating degree of security protection);
perform at least one of: changing a current level among the at least two levels to increase the degree of the security protection state indicated by the first reliability when the integrity check has been successfully completed; or changing the current level among the at least two levels to diminish the degree of the security protection state indicated by the first reliability when the integrity check has not been successfully completed (HAREL on [0180-0181] teaches If at 1140 the database query indicates that data or a record exists for the driving assistance information, then at 1160 another determination is made. If information from the database and the information extracted from the sensor data are substantially the same, then the confidence level associated with the existing database information is increased. Further teaches If, at 1140, the information from the database and the information extracted from the sensor data are not substantially the same, then the confidence level associated with the existing database information is decreased at 1170. For example, the 70% confidence level associated with the accuracy of the speed limit of the road near the landmark 860a can be reduced to 69%, 68%, 60%, or any other appropriate decreased value);
Although HAREL teaches performing integrity check, but fails to explicitly teach perform integrity check of software of the first monitoring target by reading a memory region of the software of the first monitoring target, calculating a hash value of the memory region, and comparing the hash value calculated with a hash value stored in advance as correct data and in response to determining that a predetermined time has elapsed from time at which the integrity check has been performed, subtract a preset value from the first reliability to change the current level among the at least two levels to diminish the degree of the security protection state indicated by the first reliability, however HAYTON from analogous art teaches wherein the one or more processors are further configured to: perform integrity check of software of the first monitoring target by reading a memory region of the software of the first monitoring target, calculating a hash value of the memory region, and comparing the hash value calculated with a hash value stored in advance as correct data (HAYTON [0064-0665 and 0177] teaches calculating hash of memory region and comparing the hash with expected hash code to validate software’s integrity. For example, the device 2 may check whether the result of hashing contents of a specified memory region matches an expected hash value, to check whether a required piece of software is still installed at that memory region and has not been modified).
Thus, it would have been obvious to one ordinary skill in the art before the effective filing date to implement the teaching of HAYTON into the teaching of HAREL by calculating and comparing hash value of memory region holding the software. One would be motivated to do so in order to validate integrity of software stored in particular memory region (HAYTON [0003-0010 and 0064-0065]).
The combination fails to explicitly teach in response to determining that a predetermined time has elapsed from time at which the integrity check has been performed, subtract a preset value from the first reliability to change the current level among the at least two levels to diminish the degree of the security protection state indicated by the first reliability, however Minezaki from analogous art teaches
in response to determining that a predetermined time has elapsed from time at which the integrity check has been performed, subtract a preset value from the first reliability to change the current level among the at least two levels to diminish the degree of the security protection state indicated by the first reliability (Minezaki on [0115] teaches first, the CPU core 215 makes a request of a target CPU package 211 and acquires the value of the correctable error counter register 217 (S31). Then, the CPU core 215 calculates an increment given by an elapse of a certain time period by subtracting from the value a previously acquired value, and saves a newly-acquired value. See on [0153 and 0178] teaches The CPU monitor 840 includes a correctable error acquiring unit 841. The correctable error acquiring unit 841 regularly acquires a value of the correctable error counter register 217 from each of the CPU packages 211, calculates an increment by subtracting from the acquired value a previously acquired value, and updates the correctable-error-accumulated information 821 by use of the calculated increment).
Thus, it would have been obvious to one ordinary skill in the art before the effective filing date to implement the teaching of Minezaki into the combined teaching of HAREL and HAYTON by calculating and comparing hash value of memory region holding the software. One would be motivated to do so in order to monitor and identify failure in virtual machine (Minezaki [0112-0115]).
Regarding claim 2 the combination of HAREL, HAYTON and Minezaki teaches all the limitations of claim 1 above, HAYTON further teaches wherein the integrated ECU further operates a trusted execution environment (TEE), and the integrity check is performed on the TEE (HAYTON on [0076] teaches the storage circuitry 6 may have a secure region 8 which is protected by hardware mechanisms (e.g. using memory protection units or security mechanisms providing a trusted execution environment) or by software mechanisms (e.g. encryption), so that data stored in a secure region 8 is inaccessible to software not executing within the trusted environment).
Thus, it would have been obvious to one ordinary skill in the art before the effective filing date to implement the teaching of HAYTON into the teaching of HAREL by calculating and comparing hash value of memory region holding the software. One would be motivated to do so in order to validate integrity of software stored in particular memory region (HAYTON [0003-0010 and 0064-0065]).
Regarding claim 3 the combination of HAREL, HAYTON and Minezaki teaches all the limitations of claim 1 above HAREL further teaches wherein the plurality of virtual machines that are capable of being operated by the integrated ECU operate on a hypervisor, and the monitoring system further monitors the hypervisor (HAREL on [0121-0123] teaches when an image is being serviced, a hypervisor of the image can be used for these types of tasks. This may be beneficial as a hypervisor can be made more difficult than native code to detect by malicious actors. On real ECUs, sensor software can be added to ECU software, and on images the sensors can be included, for example, in hypervisors).
Regarding claim 4 the combination of HAREL, HAYTON and Minezaki teaches all the limitations of claim 1 above HAREL further teaches further comprising: a function restrictor circuit that places a restriction on at least a part of functions of the first monitoring target according to the first reliability (HAREL on [0179] teaches a newly added landmark may be given a low confidence level, such as 1%, 5%, or 10%, to prevent the information from being used to alter vehicular behavior until the landmark can be confirmed).
Regarding claim 5 the combination of HAREL, HAYTON and Minezaki teaches all the limitations of claim 1 above HAREL further teaches wherein the monitoring system causes the first monitoring target to perform reboot (GALULA on [0047 and 0055] teaches if verification, authentication or validation of executable code fails, a system may take preventative actions, e.g., kill or stop execution of the relevant process (violating process), reboot a system, revert to a known state of a system).
Regarding claim 6 the combination of HAREL, HAYTON and Minezaki teaches all the limitations of claim 5 above HAREL further teaches wherein the monitoring system changes the current level among the at least two levels to increase the degree of the security protection state indicated by the first reliability or change the first reliability to an initial value (HAREL on [0180-0181] teaches If at 1140 the database query indicates that data or a record exists for the driving assistance information, then at 1160 another determination is made. If information from the database and the information extracted from the sensor data are substantially the same, then the confidence level associated with the existing database information is increased. Further teaches If, at 1140, the information from the database and the information extracted from the sensor data are not substantially the same, then the confidence level associated with the existing database information is decreased at 1170. For example, the 70% confidence level associated with the accuracy of the speed limit of the road near the landmark 860a can be reduced to 69%, 68%, 60%, or any other appropriate decreased value).
HAYTON teaches (HAYTON on [0241] teaches After device “birth” the audit logging functionality could be disposed of (similar to discarding the event attestations or keys/identifiers used for the Birth phase once the device access to the service has been enabled) or alternatively turned off—i.e. it may only serve to detect fraudulent ODMs, it need not be considered to always be active. See on [0069] teaches If the device is “reborn” in this way, then it may need new event attestations to be installed on the device in order to be able to re-register for a service again, as the previously installed event attestations may have been deleted when registering for the previous service as discussed above. Therefore, the rebirth request sent by the service provider may comprise at least one rebirth event attestation attesting to occurrence of at least one event, and in response to the rebirth request, the processing circuitry may store the at least one rebirth event attestation to storage circuitry for generating the attestation information for a subsequent validation request).
Thus, it would have been obvious to one ordinary skill in the art before the effective filing date to implement the teaching of HAYTON into the teaching of HAREL by calculating and comparing hash value of memory region holding the software. One would be motivated to do so in order to validate integrity of software stored in particular memory region (HAYTON [0003-0010 and 0064-0065]).
Regarding claim 7 the combination of HAREL, HAYTON and Minezaki teaches all the limitations of claim 5 above HAREL further teaches wherein the monitoring system determines whether the first reliability of the first monitoring target is less than a threshold value, and causes the first monitoring target to execute the reboot when the first reliability is less than the threshold value (HAREL on [0193] teaches if at 1250, the confidence level does not satisfy the predetermined threshold, then at 1280 the driving assistance (e.g., sign or landmark) information is not provided as part of the road information. For example, if the confidence associated with the information 880a is low enough (e.g., below the threshold) then the landmark (e.g., the misidentified “zombie x-ing” t-shirt) may not be treated as being “real” and therefore unnecessary to obey. See on [0195] teaches if the confidence level of the particular driving assistance information (e.g., sign or other landmark) fails to satisfy the predetermined removal threshold, then the information about the landmark is removed from the database)
Regarding claim 8 the combination of HAREL, HAYTON and Minezaki teaches all the limitations of claim 4 above HAYTON further teaches wherein the restriction on the at least the part of the functions of the first monitoring target according to the first reliability of the first monitoring target includes suspending an access right to access a particular resource by the first monitoring target (HAYTON on [0097] teaches an event attestation could be limited to being used on a certain number of devices (e.g. the number of devices in the batch that were originally injected with that event attestation), and the validation apparatus (or a service provider apparatus) could compare the usage count with a set threshold to determine whether the device should be accepted. See on [0070] teaches , the rebirth event attestation may be such that effectively the device is limited to being re-registered with the same service provider as before (e.g. the service provider may trust its own event attestation that the device previously met the requirements for that service and so can re-enrol the device again for a subsequent attempt. See on [0079] teaches the attestation database 62 may also include lists of revoked attestations or information about allowed usage limits for attestations).
Thus, it would have been obvious to one ordinary skill in the art before the effective filing date to implement the teaching of HAYTON into the teaching of HAREL by calculating and comparing hash value of memory region holding the software. One would be motivated to do so in order to validate integrity of software stored in particular memory region (HAYTON [0003-0010 and 0064-0065]).
Regarding claim 13 the combination of HAREL, HAYTON and Minezaki teaches all the limitations of claim 1 above GALULA further teaches further comprising: a display unit that displays the first monitoring target and the first reliability together (HAYTON on [0075] teaches , some devices for which user interaction is expected may be provided with a display and/or a user interface module in order to display information to the user and receive input from the user. Other types of devices may simply be sensors which capture data and transmit the data to an external device and so these types of devices may not need a user interface or display).
Thus, it would have been obvious to one ordinary skill in the art before the effective filing date to implement the teaching of HAYTON into the teaching of HAREL by displaying information in display unit of the device. One would be motivated to do so in order to visually analyze and monitor the performance of the device (HAYTON [0003-0010 and 0064-0065]).
Regarding claim 14 the combination of HAREL, HAYTON and Minezaki teaches all the limitations of claim 4 above HAREL further teaches wherein the one or more processors and the function restrictor circuit are mounted in the vehicle (HAREL Fig 1 and text on [0086-0092] teaches attack analyzer associated with vehicle. See on [0157-0163] teaches collection of vehicles 850a-850c are in communication with the server 105. Each of the vehicles 850a-850c is equipped with sensors and processors that can sense the presence and location of various landmarks in the surrounding environment. Such sensors will be discussed further in the description of FIG. 9. As the vehicles 850a-850c moves through its environment (e.g., road), they detect the presence or absence of nearby road status information, such as road signs and other roadside landmarks).
Regarding claim 15 the combination of HAREL, HAYTON and Minezaki teaches all the limitations of claim 4 above HAREL further teaches wherein the monitoring system includes a server that is communicatively connected to the vehicle, and at least one of the one or more processor or the function restrictor circuit is implemented in the server (HAREL Fig 2 and text on [0020, 0157 and 0095-0098] teaches server coupled to vehicle).
Regarding claim 16 HAREL teaches a monitoring method for monitoring a vehicle or an integrated electronic control unit (ECU) in which functions of a plurality of ECUs are integrated and that operates inside the vehicle (HAREL on [0011 and 0087] teaches system and method for monitoring ECUs in vehicle to protect against cyber security attack. See also on [0123] teaches system that monitors all traffic to and from the ECUs);
the integrated ECU being capable of operating a plurality of virtual machines, each of the plurality of virtual machines including a function of at least one ECU among functions of the plurality of ECUs (HAREL on [0023, 0115, 0119, 0123] teaches ECU operating plurality of virtual machine. See on [0104-0107] teaches the virtual machine 306, being a honeypot, may be configured with security and monitoring features so that, when a malicious attack is performed on the virtual machine 306, that attack is trapped or “sandboxed” within the virtual machine 306. Operations of the attack such as system calls, network communication, and the like can be recorded by the virtual machine 306. i.e., virtual machine with function of ECUs);
wherein the monitoring method comprises reliability managing that handles one of the plurality of virtual machines as a monitoring target for monitoring the functions of the plurality of ECUs (HAREL on [0088-0090] teaches an attack analyzer 106 can be configured to monitor the malicious attacks 102 on the trap-images 104 and record information about the attacks. The trap images 104 are images of software of ECUs that are to be hardened. See on [0104-0107] the virtual machine 306, being a honeypot, may be configured with security and monitoring features so that, when a malicious attack is performed on the virtual machine 306, that attack is trapped or “sandboxed” within the virtual machine 306. Operations of the attack such as system calls, network communication, and the like can be recorded by the virtual machine 306. i.e., virtual machine with function of ECUs. Further teaches an attack on the library 308 may attempt to use a buffer-overrun exploit to initiate execution of arbitrary code within the virtual machine 306. When this attack is attempted (whether successful or unsuccessful) the virtual machine 306 can record actions taken. In some cases, elements of the virtual machine are inaccessible to the environment in which the libraries 308 execute, and one or more supervisors in those elements monitor the actions in the environment. See on [0123] teaches the trap image server system 204 can monitor all network traffic to and from the ECUs. See on [0130 and 0135] teaches the hosting system can monitor network traffic and the state of the VM for events that match a rule-set of states indicative of a malicious attack);
and managing reliability indicating a security protection state of the monitoring target, the reliability being a variable capable of taking at least two levels each of which indicates a degree of the security protection state of the monitoring target, and the monitoring method comprises: (HAREL on [0174] teaches confidence value or metric that indicates a variable level of certainty that the information about a particular sign, road, restriction, limit, location, or other attribute or object is accurate. See on [0179 and 0192-0194] teaches , a newly added landmark may be given a low confidence level, such as 1%, 5%, or 10%, to prevent the information from being used to alter vehicular behavior until the landmark can be confirmed and high confidence level. i.e., at least two levels low and high indicating degree of security protection);
performing at least one of: changing a current level among the at least two levels to increase the degree of the security protection state indicated by the reliability when the integrity check has been successfully completed; or changing the current level among the at least two levels to diminish the degree of the security protection state indicated by the reliability when the integrity check has not been successfully completed (HAREL on [0180-0181] teaches If at 1140 the database query indicates that data or a record exists for the driving assistance information, then at 1160 another determination is made. If information from the database and the information extracted from the sensor data are substantially the same, then the confidence level associated with the existing database information is increased. Further teaches If, at 1140, the information from the database and the information extracted from the sensor data are not substantially the same, then the confidence level associated with the existing database information is decreased at 1170. For example, the 70% confidence level associated with the accuracy of the speed limit of the road near the landmark 860a can be reduced to 69%, 68%, 60%, or any other appropriate decreased value).
Although HAREL teaches performing integrity check, but fails to explicitly teach perform integrity check of software of the first monitoring target by reading a memory region of the software of the first monitoring target, calculating a hash value of the memory region, and comparing the hash value calculated with a hash value stored in advance as correct data and in response to determining that a predetermined time has elapsed from time at which the integrity check has been performed, subtract a preset value from the first reliability to change the current level among the at least two levels to diminish the degree of the security protection state indicated by the first reliability, however HAYTON from analogous art teaches wherein the one or more processors are further configured to: perform integrity check of software of the first monitoring target by reading a memory region of the software of the first monitoring target, calculating a hash value of the memory region, and comparing the hash value calculated with a hash value stored in advance as correct data (HAYTON [0064-0665 and 0177] teaches calculating hash of memory region and comparing the hash with expected hash code to validate software’s integrity. For example, the device 2 may check whether the result of hashing contents of a specified memory region matches an expected hash value, to check whether a required piece of software is still installed at that memory region and has not been modified).
Thus, it would have been obvious to one ordinary skill in the art before the effective filing date to implement the teaching of HAYTON into the teaching of HAREL by calculating and comparing hash value of memory region holding the software. One would be motivated to do so in order to validate integrity of software stored in particular memory region (HAYTON [0003-0010 and 0064-0065]).
The combination fails to explicitly teach in response to determining that a predetermined time has elapsed from time at which the integrity check has been performed, subtract a preset value from the first reliability to change the current level among the at least two levels to diminish the degree of the security protection state indicated by the first reliability, however Minezaki from analogous art teaches
in response to determining that a predetermined time has elapsed from time at which the integrity check has been performed, subtract a preset value from the first reliability to change the current level among the at least two levels to diminish the degree of the security protection state indicated by the first reliability (Minezaki on [0115] teaches first, the CPU core 215 makes a request of a target CPU package 211 and acquires the value of the correctable error counter register 217 (S31). Then, the CPU core 215 calculates an increment given by an elapse of a certain time period by subtracting from the value a previously acquired value, and saves a newly-acquired value. See on [0153 and 0178] teaches The CPU monitor 840 includes a correctable error acquiring unit 841. The correctable error acquiring unit 841 regularly acquires a value of the correctable error counter register 217 from each of the CPU packages 211, calculates an increment by subtracting from the acquired value a previously acquired value, and updates the correctable-error-accumulated information 821 by use of the calculated increment).
Thus, it would have been obvious to one ordinary skill in the art before the effective filing date to implement the teaching of Minezaki into the combined teaching of HAREL and HAYTON by calculating and comparing hash value of memory region holding the software. One would be motivated to do so in order to monitor and identify failure in virtual machine (Minezaki [0112-0115]).
Regarding claim 17 HAREL teaches a monitoring device for monitoring a vehicle or an integrated electronic control unit (ECU) in which functions of a plurality of ECUs are integrated and that operates inside the vehicle (HAREL on [0011 and 0087] teaches system and method for monitoring ECUs in vehicle to protect against cyber security attack. See also on [0123] teaches system that monitors all traffic to and from the ECUs);
the integrated ECU being capable of operating a plurality of virtual machines, each of the plurality of virtual machines including a function of at least one ECU among functions of the plurality of ECUs (HAREL on [0023, 0115, 0119, 0123] teaches ECU operating plurality of virtual machine. See on [0104-0107] teaches the virtual machine 306, being a honeypot, may be configured with security and monitoring features so that, when a malicious attack is performed on the virtual machine 306, that attack is trapped or “sandboxed” within the virtual machine 306. Operations of the attack such as system calls, network communication, and the like can be recorded by the virtual machine 306. i.e., virtual machine with function of ECUs);
wherein the monitoring device comprises one or more processors and one or more memories, wherein the one or more processors are configured to handle one of the plurality of virtual machines as a first monitoring target for monitoring the functions of the plurality of ECUs (HAREL on [0088-0090] teaches an attack analyzer 106 can be configured to monitor the malicious attacks 102 on the trap-images 104 and record information about the attacks. The trap images 104 are images of software of ECUs that are to be hardened. See on [0104-0107] the virtual machine 306, being a honeypot, may be configured with security and monitoring features so that, when a malicious attack is performed on the virtual machine 306, that attack is trapped or “sandboxed” within the virtual machine 306. Operations of the attack such as system calls, network communication, and the like can be recorded by the virtual machine 306. i.e., virtual machine with function of ECUs. Further teaches an attack on the library 308 may attempt to use a buffer-overrun exploit to initiate execution of arbitrary code within the virtual machine 306. When this attack is attempted (whether successful or unsuccessful) the virtual machine 306 can record actions taken. In some cases, elements of the virtual machine are inaccessible to the environment in which the libraries 308 execute, and one or more supervisors in those elements monitor the actions in the environment. See on [0123] teaches the trap image server system 204 can monitor all network traffic to and from the ECUs. See on [0130 and 0135] teaches the hosting system can monitor network traffic and the state of the VM for events that match a rule-set of states indicative of a malicious attack. See on [0003-0004 and 0142-0148] teaches electronic controller having processor and memory);
and manages first reliability indicating a security protection state of the first monitoring target, the first reliability being a variable capable of taking at least two levels each of which indicates a degree of the security protection state of the first monitoring target (HAREL on [0174] teaches confidence value or metric that indicates a variable level of certainty that the information about a particular sign, road, restriction, limit, location, or other attribute or object is accurate. See on [0179 and 0192-0194] teaches , a newly added landmark may be given a low confidence level, such as 1%, 5%, or 10%, to prevent the information from being used to alter vehicular behavior until the landmark can be confirmed and high confidence level. i.e., at least two levels low and high indicating degree of security protection);
performs at least one of: changing a current level among the at least two levels to increase the degree of the security protection state indicated by the first reliability when the integrity check has been successfully completed; or changing the current level among the at least two levels to diminish the degree of the security protection state indicated by the first reliability when the integrity check has not been successfully completed (HAREL on [0180-0181] teaches If at 1140 the database query indicates that data or a record exists for the driving assistance information, then at 1160 another determination is made. If information from the database and the information extracted from the sensor data are substantially the same, then the confidence level associated with the existing database information is increased. Further teaches If, at 1140, the information from the database and the information extracted from the sensor data are not substantially the same, then the confidence level associated with the existing database information is decreased at 1170. For example, the 70% confidence level associated with the accuracy of the speed limit of the road near the landmark 860a can be reduced to 69%, 68%, 60%, or any other appropriate decreased value).
Although HAREL teaches performing integrity check, but fails to explicitly teach perform integrity check of software of the first monitoring target by reading a memory region of the software of the first monitoring target, calculating a hash value of the memory region, and comparing the hash value calculated with a hash value stored in advance as correct data and in response to determining that a predetermined time has elapsed from time at which the integrity check has been performed, subtract a preset value from the first reliability to change the current level among the at least two levels to diminish the degree of the security protection state indicated by the first reliability, however HAYTON from analogous art teaches wherein the one or more processors are further configured to: perform integrity check of software of the first monitoring target by reading a memory region of the software of the first monitoring target, calculating a hash value of the memory region, and comparing the hash value calculated with a hash value stored in advance as correct data (HAYTON [0064-0665 and 0177] teaches calculating hash of memory region and comparing the hash with expected hash code to validate software’s integrity. For example, the device 2 may check whether the result of hashing contents of a specified memory region matches an expected hash value, to check whether a required piece of software is still installed at that memory region and has not been modified).
Thus, it would have been obvious to one ordinary skill in the art before the effective filing date to implement the teaching of HAYTON into the teaching of HAREL by calculating and comparing hash value of memory region holding the software. One would be motivated to do so in order to validate integrity of software stored in particular memory region (HAYTON [0003-0010 and 0064-0065]).
The combination fails to explicitly teach in response to determining that a predetermined time has elapsed from time at which the integrity check has been performed, subtract a preset value from the first reliability to change the current level among the at least two levels to diminish the degree of the security protection state indicated by the first reliability, however Minezaki from analogous art teaches
in response to determining that a predetermined time has elapsed from time at which the integrity check has been performed, subtract a preset value from the first reliability to change the current level among the at least two levels to diminish the degree of the security protection state indicated by the first reliability (Minezaki on [0115] teaches first, the CPU core 215 makes a request of a target CPU package 211 and acquires the value of the correctable error counter register 217 (S31). Then, the CPU core 215 calculates an increment given by an elapse of a certain time period by subtracting from the value a previously acquired value, and saves a newly-acquired value. See on [0153 and 0178] teaches The CPU monitor 840 includes a correctable error acquiring unit 841. The correctable error acquiring unit 841 regularly acquires a value of the correctable error counter register 217 from each of the CPU packages 211, calculates an increment by subtracting from the acquired value a previously acquired value, and updates the correctable-error-accumulated information 821 by use of the calculated increment).
Thus, it would have been obvious to one ordinary skill in the art before the effective filing date to implement the teaching of Minezaki into the combined teaching of HAREL and HAYTON by calculating and comparing hash value of memory region holding the software. One would be motivated to do so in order to monitor and identify failure in virtual machine (Minezaki [0112-0115]).
Regarding claim 18 the combination of HAREL, HAYTON and Minezaki teaches all the limitations of claim 1 above HAREL further teaches wherein the one or more memories store reliability management information in which the first monitoring target and the first reliability are associated with each other (HAREL on [0090] teaches an attack analyzer 106 can be configured to monitor the malicious attacks 102 on the trap-images 104 and record information about the attacks. For example, the attack analyzer 106 may have a rule-set that identifies when a malicious attack has happened as opposed to a communication being a benign interaction from another system. The attack analyzer 106 may log information from any interaction or from malicious attacks. This log of information may include, for example, a timestamp, a source network address, a source geographical address, a communication protocol, a listing of commands received, etc. See on [0120] teaches the trap image server system 204 transmits 414 images records to the attack analyzer 106. For example, the trap image server system 204 can store the logs of the attack in the fingerprint datastore 210 and the attack analyzer 106 can access the logs from the fingerprint datastore 210. See on [0131 and 0136] teaches library records are generated 508. For example, network traffic and state information of the VM may be recorded and indexed).
Claims 9-12 are rejected under 35 U.S.C. 103 as being unpatentable over HAREL et al (hereinafter HAREL) (US 20230275877) in view of HAYTON et al (hereinafter HAYTON) (US 20180198604) in view of Minezaki (US 20160004554) and further in view of GALULA et al (hereinafter GALULA) (US 20200216097).
Regarding claim 9 the combination of HAREL, HAYTON and Minezaki teaches all the limitations of claim 8 above, the combination fails to explicitly teach wherein the restriction on the at least the part of the functions according to the first reliability of the first monitoring target includes suspending a communication function of the first monitoring target, however GALULA from analogous art teaches wherein the restriction on the at least the part of the functions according to the first reliability of the first monitoring target includes suspending a communication function of the first monitoring target (GALULA on [0054-0055] teaches when security layer 210 identifies or detects a dirty, unexpected or suspicious operation or event, security layer 210 kills (e.g. terminates execution of) a process and/or reverts a component or system to a known or predefined state. See on [0047, and 0052-0053] teaches preventive action may be performed upon failure to verify, authenticate or validate executable, e.g., security layer 210 may, upon failure as described, disable a component connected to an in-vehicle network, activate a component connected to the network, block a message, delay a message, limit a frequency of a message type, log a message and/or generate an alert).
Thus, it would have been obvious to one ordinary skill in the art before the effective filing date to implement the teaching of GALULA into the combined teaching of HAREL, HAYTON and Minezaki by suspending a communication function of the first monitoring target. One would be motivated to do so in order to detect and prevent of exploitation of components connected to an in-vehicle network (GALULA [0001]).
Regarding claim 10 the combination of HAREL, HAYTON and Minezaki teaches all the limitations of claim 4 above, the combination fails to teach wherein the restriction on the at least the part of the functions of the first monitoring target according to the first reliability of the first monitoring target includes suspending a communication function of the first monitoring target, and in a case where the first monitoring target tries to communicate with a communication target, the function restrictor forbids the first monitoring target from communicating with the communication target when the first reliability is less than the threshold value
GALULA teaches wherein the restriction on the at least the part of the functions of the first monitoring target according to the first reliability of the first monitoring target includes suspending a communication function of the first monitoring target, and in a case where the first monitoring target tries to communicate with a communication target, the function restrictor forbids the first monitoring target from communicating with the communication target when the first reliability is less than the threshold value (GALULA on [0054-0055] teaches when security layer 210 identifies or detects a dirty, unexpected or suspicious operation or event, security layer 210 kills (e.g. terminates execution of) a process and/or reverts a component or system to a known or predefined state. See on [0047, and 0052-0053] teaches preventive action may be performed upon failure to verify, authenticate or validate executable, e.g., security layer 210 may, upon failure as described, disable a component connected to an in-vehicle network, activate a component connected to the network, block a message, delay a message, limit a frequency of a message type, log a message and/or generate an alert. See on [0073] teaches any policy, rules, criteria or thresholds may be used by heuristic engine 230 to identify or detect an anomalous or suspicious behavior).
Thus, it would have been obvious to one ordinary skill in the art before the effective filing date to implement the teaching of GALULA into the combined teaching of HAREL, HAYTON and Minezaki by suspending a communication function of the first monitoring target. One would be motivated to do so in order to detect and prevent of exploitation of components connected to an in-vehicle network (GALULA [0001]).
Regarding claim 11 the combination of HAREL, HAYTON and Minezaki teaches all the limitations of claim 9 above, HAREL further teaches wherein the monitoring system further handles, as a second monitoring target, one virtual machine other than the first monitoring target among the plurality of virtual machines, the reliability manager further manages second reliability indicating a security protection state of the second monitoring target (HAREL on [0017 and 0108] teaches in a first time: host one or more first virtual machines, each of the virtual machines comprising one or more first libraries identified by specifications for an electronic control unit (ECU); expose the first virtual machines to a data network such that malicious attacks against the first virtual machines are possible over the data network; generate first records of the malicious attacks against the first virtual machines; in a second time after the first time: host one or more second virtual machines, each of the second virtual machines comprising an ECU image that comprise second libraries; expose the second virtual machines to the data network such that malicious attacks against the second virtual machines are possible over the data network; and generate second records of the malicious attacks against the second virtual machines. See on [0119] teaches the ECU image can be used in a virtual machine that emulates an ECU. Malicious attacks on the virtual machine can be observed and logged.)
The combination fails to teach in a case where the first monitoring target and the second monitoring target try to communicate with each other, the function restrictor forbids the first monitoring target and the second monitoring target from communicating with each other when at least one of the first reliability or the second reliability is less than a threshold value, however GALULA from analogous art teaches in a case where the first monitoring target and the second monitoring target try to communicate with each other, the function restrictor circuit forbids the first monitoring target and the second monitoring target from communicating with each other when at least one of the first reliability or the second reliability is less than a threshold value (GALULA on [0054-0055] teaches when security layer 210 identifies or detects a dirty, unexpected or suspicious operation or event, security layer 210 kills (e.g. terminates execution of) a process and/or reverts a component or system to a known or predefined state. See on [0047, and 0052-0053] teaches preventive action may be performed upon failure to verify, authenticate or validate executable, e.g., security layer 210 may, upon failure as described, disable a component connected to an in-vehicle network, activate a component connected to the network, block a message, delay a message, limit a frequency of a message type, log a message and/or generate an alert. See on [0073] teaches any policy, rules, criteria or thresholds may be used by heuristic engine 230 to identify or detect an anomalous or suspicious behavior).
Thus, it would have been obvious to one ordinary skill in the art before the effective filing date to implement the teaching of GALULA into the combined teaching of HAREL, HAYTON and Minezaki by forbidding the first monitoring target and the second monitoring target from communicating with each other when at least one of the first reliability or the second reliability is less than a threshold value. One would be motivated to do so in order to detect and prevent of exploitation of components connected to an in-vehicle network (GALULA [0001]).
Regarding claim 12 the combination of HAREL, HAYTON and Minezaki teaches all the limitations of claim 4 above, the combination fails to teach wherein the restriction on the at least the part of the functions according to the first reliability of the first monitoring target includes suspending an operation of the first monitoring target, however GALULA teaches wherein the restriction on the at least the part of the functions according to the first reliability of the first monitoring target includes suspending an operation of the first monitoring target (GALULA on [0054-0055] teaches when security layer 210 identifies or detects a dirty, unexpected or suspicious operation or event, security layer 210 kills (e.g. terminates execution of) a process and/or reverts a component or system to a known or predefined state. See on [0047, and 0052-0053] teaches preventive action may be performed upon failure to verify, authenticate or validate executable, e.g., security layer 210 may, upon failure as described, disable a component connected to an in-vehicle network, activate a component connected to the network, block a message, delay a message, limit a frequency of a message type, log a message and/or generate an alert).
Thus, it would have been obvious to one ordinary skill in the art before the effective filing date to implement the teaching of GALULA into the combined teaching of HAREL, HAYTON and Minezaki by suspending a communication function of the first monitoring target. One would be motivated to do so in order to detect and prevent of exploitation of components connected to an in-vehicle network (GALULA [0001]).
Conclusion
Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a).
A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action.
Any inquiry concerning this communication or earlier communications from the examiner should be directed to MOEEN KHAN whose telephone number is (571)272-3522. The examiner can normally be reached 7AM-5PM EST M-TH Alternate Fridays.
Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice.
If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Shewaye Gelagay can be reached at (571)272-4219. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300.
Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000.
/MOEEN KHAN/Primary Examiner, Art Unit 2436